为何Elasticsearch中_cat/templates可见flowlogtmplt但_index_template查询返回404?
问题:为什么Elasticsearch不识别flowlogtmplt为索引模板?
执行GET _cat/templates?v时,返回以下两个模板:
"1": { "name": "flowlogtmplt", "index_patterns": "[flowlog*, flowobsrv*]", "order": "0", "version": null, "composed_of": "" }, "14": { "name": "flowlog", "index_patterns": "[flowlog-*]", "order": "0", "version": null, "composed_of": "[]" },
但使用GET /_index_template/查询时,只有flowlog能返回结果:
查询flowlog的结果
{ "index_templates": [ { "name": "flowlog", "index_template": { "index_patterns": [ "flowlog-*" ], "template": { "settings": { "index": { "lifecycle": { "name": "flowlog" } } } }, "composed_of": [] } } ] }
查询flowlogtmplt返回404错误
{ "error": { "root_cause": [ { "type": "resource_not_found_exception", "reason": "index template matching [flowlogtmplt] not found" } ], "type": "resource_not_found_exception", "reason": "index template matching [flowlogtmplt] not found" }, "status": 404 }
原因说明
这是因为flowlogtmplt属于旧版索引模板(Legacy Index Template),而GET /_index_template/接口仅支持查询Elasticsearch 7.8及以上版本推出的组件化索引模板(Composable Index Template)——也就是你能正常查到的flowlog这类模板。
两类模板属于不同的系统:
- 旧版模板通过
PUT _template/模板名创建,只能用GET _template/模板名或GET _cat/templates查询 - 新版组件化模板通过
PUT _index_template/模板名创建,对应使用GET _index_template/模板名查询
_cat/templates会同时展示旧版和新版模板,所以你能看到两个条目,但_index_template接口只识别新版组件化模板,因此查询旧版的flowlogtmplt会返回404。
内容的提问来源于stack exchange,提问作者NeilB
相关产品推荐
相关产品推荐

